Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo RHEEM.COM

Group: Clop

Discovered by ransomware.live: 2025-11-07

Estimated attack date: 2025-11-07

Country: US

Description:

[AI generated] Rheem Manufacturing Company is a leading global manufacturer of heating, cooling, water heating, and pool/spa heating solutions. It is headquartered in Atlanta, Georgia, USA. Since it's founded in 1925, Rheem has aimed to help people improve their comforts at home and at various business establishments. This widely recognized corporation offers advanced, energy-efficient options and diversified its product lineup to meet varying consumer needs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 100

Third Party Employee Credentials: 29


External Attack Surface: 41


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • rheem-com.mail.protection.outlook.com.
TXT Records
  • adobe-sign-verification=d6c2ed0df422a001eaaf5de9729aba4e
  • dropbox-domain-verification=fgeb444uulxq
  • atlassian-domain-verification=Lrl4cX3kM3FF4NhW4wIQAZXbGwZxv4GOeoH2UdAs6G/1A9mKkztBogwJ7hQJVXsI
  • google-site-verification=Lbbz0Kz5WrQ54aUYmpHJrCbV-CxpU4LZ1oGrBD194hs
  • v=spf1 ip4:63.76.193.37 ip4:63.76.193.12 ip4:66.231.88.207 ip4:66.231.89.168 ip4:107.23.16.222 ip4:54.173.83.138 ip4:208.85.50.148 ip4:35.80.141.6 ip4:44.229.121.55 ip4:54.205.217.180 ip4:20.119.163.56 ip4:148.59.100.16/28" " include:_spf.psm.knowbe4.com include:servers.mcsv.net include:spf.ipzmarketing.com include:spf_c.oraclecloud.com include:spf.icontroller.eu include:spf.protection.outlook.com include:_spf.e2ma.net include:rp.oracleemaildelivery.com -all
Cloud / SaaS Services Detected
Atlassian Dropbox Mailchimp Box Oracle Cloud KnowBe4

Leak Screenshot:

Leak Screenshot